Security controls you can verify.
Brolly holds the records your organisation may one day need to produce for an FOI request, an audit or a court. That responsibility shapes how the platform is built, audited and operated — and everything on this page is verifiable. Questions go to security@brolly.com.au.
Independently certified, not self-declared.
Certified
ISO/IEC 27001:2022
Brolly Australasia Pty Ltd holds a certified information security management system — the international benchmark, audited independently.
✓Download the certificate (PDF)
Registered
CSA STAR
Registered with the Cloud Security Alliance's Security, Trust & Assurance Registry.
✓View the public registry listingAustralian ISM & Essential Eight
Practices aligned to the Australian Government Information Security Manual and the ASD Essential Eight mitigation strategies.
✓Control mapping on requestBuilt for the rules your records live under.
Brolly's security practices are aligned to the Australian Government Information Security Manual (ISM) and the ASD Essential Eight. These frameworks guide how we approach security, risk management and operational resilience for councils, agencies and regulated organisations. For multinational or US reviews, our controls are also mapped to NIST SP 800-53.
| Your obligation | What it demands | How Brolly answers |
|---|---|---|
| State records legislation & FOI / GIPA / RTI | Produce responsive, unaltered records on request — including edited and deleted content | Near-real-time capture, revision history, response-ready exports with digital checksums |
| ASIC RG 271 (financial services) | Handle complaints made through social media like any other complaint, with a record | Records retained until you authorise disposal, with audit trails |
| Health & education communities | Handle sensitive communities' communications with care and accountability | Role-based access, moderation with preserved records, audit logs |
| Retention and disposal authorities | Keep records for the required periods, then dispose of them defensibly | Configurable retention aligned to your retention and disposal authority |
The controls, in plain English.
Where your data lives: Your data is stored on AWS cloud servers located in Australia. Brolly is 100% Australian owned and operated, and Brolly Australasia Pty Ltd is the certified entity.
Encryption everywhere
AES-256 at rest, TLS 1.3+ in transit. Records carry audit logs; exports carry digital checksums.
Access control
Multi-factor authentication and role-based access — records team, comms team and legal each see what their role requires.
Tested by attackers
Independent penetration testing and a secure development lifecycle guided by OWASP practices.
Reliable by design
Redundant AWS architecture in Australia across multiple availability zones, encrypted backups, and an availability commitment set out in our service level agreement.
Signed in to Brolly — MFA verified
203.0.113.24Willowdale, AUSuccessConnected Facebook Page — Willowdale Shire
203.0.113.24Willowdale, AUSuccessExported archive — Q1 records package (PDF)
203.0.113.61Willowdale, AUSuccessChanged M. Okafor's role from Member to Owner
203.0.113.24Willowdale, AUSuccessIncorrect password — 3 attempts
198.51.100.7UnknownFailedYour records are yours.
Brolly never sells customer data and never shares it for third-party advertising. Approved subprocessors, such as our hosting providers, process it only to provide and secure the service under contractual safeguards. Our privacy practices are built around the Australian Privacy Act and the Australian Privacy Principles, with GDPR-ready handling where you need it and data deletion honoured per our published process.
What your security team will ask.
Is Brolly ISO 27001 certified?
Which frameworks do Brolly’s controls align to?
Is our data stored in Australia?
Do you sell or share our data?
What uptime do you commit to?
Can our security team review your controls?
Send us the questionnaire. We like them.
Certification documents, pen-test summaries and completed security reviews are available under NDA.